What the vulnerability does
01Description
Missing Authorization vulnerability in Vikas Ratudi VPSUForm v-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VPSUForm: from n/a through <= 3.0.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Vikas Ratudi VPSUForm v-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VPSUForm: from n/a through <= 3.0.5.
Explanation of Vulnerability in Simple Terms
VPSUForm versions 3.0.5 and earlier lack proper authorization checks, allowing authenticated users to modify or delete data they should not have access to. An attacker with a low-privilege account can change or remove form submissions and related records. The vulnerability requires valid login credentials but no special user role. Update to a version newer than 3.0.5.
What an attacker can do
Modify or delete form submissions and data belonging to other users or the site.
Potential impact on your site
Form data integrity is at risk; users' submissions can be altered or erased by unauthorized accounts.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges; no special role required.
Key dates
External resources
Related vulnerabilities